“Clerical Error” Results In Domain-Jacking of Swedish Social Insurance Admin’s W
SWEDEN — The Swedish Social Insurance Administration (SSIA), or “Försäkringskassan” as it is known in Swedish, has long used the domain forsakringskassan.se for its official website. Not long ago, it became possible to register domain names that include heretofore unavailable characters, including the Swedish letters å, ä and ö. When it became possible to register domain names that included the Swedish characters, the SSIA dutifully registered försäkringskassan.se.
However, a flub on the part of the II Foundation, the organization that oversees registration of all .se domain names, led to a different manner of site being displayed at försäkringskassan.se late last month.
For a brief period prior to SSIA officials being notified of the problem, visitors to försäkringskassan.se found a range of pay-per-view porn options that included “amateur,” “ethnic,” “fetish,” and “hardcore” categories of movies, instead of information on social insurance,
“I found out when I started getting calls from journalists,” SSIA spokesman Robin Lapidus told TheLocal.se, an English language site that offers news from Sweden. “We’ve spent all afternoon trying to get the site down.”
Eventually, the II Foundation took responsibility for the domain jacking, chalking it up to a “clerical error.”
The SSIA had apparently decided it no longer wanted to keep a misspelled version of its domain name – försäkringskasan.se – but when II Foundation acted on their request to drop the misspelled domain name, the foundation accidentally deregistered the wrong domain.
In September, a company based in southern Sweden snatched up the deregistered försäkringskassan.se, according to TheLocal.se, but it is believed that the porn site had not been in place long before the SSIA became aware of the problem.
“I’m not entirely sure how long it was up for, but I think it was just today,” Lapidus told TheLocal.se.
Lapidus added that he was satisfied with how the II Foundation handled the problem, once they were alerted to the situation, and the domain now redirects to the official Försäkringskassan website.
“We are very sorry for what happened and have put it down to human error” said Danny Aerts, CEO of the II Foundation. “It’s a shame that errors like this are immediately seized on by domain pirates. This case put a new focus on how easy it is for web addresses that are similar to official addresses to be used by hoaxers.”
Aerts added that II Foundation will “review our routines to stop something like this happening in the future.”